Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

CVE-2026-71543: OpenBao policies let attacker raise privileges via wildcards

CVE-2026-71543 · published 8 days ago
Summary

OpenBao lets you create policies that include placeholders, such as a user name, which are filled in when the policy is used. If an attacker can choose the placeholder value and include characters like *, + or /, they can broaden the policy to gain access to data or certificates they shouldn’t have. Restrict the characters allowed in template inputs or avoid using wildcards in these policies to prevent the escalation.

What to do
  • Update github.com openbao to version 0.0.0-20260710001938-2d4ebafec5c5.
  • Update openbao github.com/openbao/openbao to version 0.0.0-20260710001938-2d4ebafec5c5.
  • Update openbao to version 2.6.0.
Affected software
Ecosystem VendorProductAffected versions
go github.com openbao < 0.0.0-20260710001938-2d4ebafec5c5
>= 0.1.0, <= 1.1.5
Fix: upgrade to 0.0.0-20260710001938-2d4ebafec5c5
Go openbao github.com/openbao/openbao < 0.0.0-20260710001938-2d4ebafec5c5
>= 0.1.0, <= 1.1.5
Fix: upgrade to 0.0.0-20260710001938-2d4ebafec5c5
– openbao openbao <2.6.0
Bitnami – openbao < 2.6.0
Fix: upgrade to 2.6.0
Original advisory text
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowed_uri_sans_template and allowed_domains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowed_users and allowed_domains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.
Severity
7.5 High
CVSS 4.0: 7.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
Timeline
Published21 Sep 2026
Updated29 Sep 2026
First seen21 Sep 2026
Track software like this
Free during beta